Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Confirmed { "vulnerability": { "@id": "https://pkg.go.dev/vuln/GO-2026-6355", "name": "GO-2026-6355", "description": "Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh", "aliases": [ "CVE-2026-56855" ] }, "products": [ { "@id": "Unknown Product", "subcomponents": [ { "@id": "pkg:golang/golang.org%2Fx%2Fcrypto.0" } ] } ], "status": "affected" } ]